3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-3909
Premisys Identicard 3.1.190 General
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.

CVE-2019-16913
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permission "Everyone: (F)" to the contents of the directory and its subfolders. In addition, the program installs a service called SecurityService that runs as LocalSystem. This allows any user to escalate privileges to "NT AUTHORITY\SYSTEM" by substituting the service's binary with a Trojan horse.

CVE-2019-19224
Software Genérico General
N/A
UNKNOWN
EPSS
2.4%
2019 1 PoC

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the configuration (binary file) settings by submitting a rom-0 GET request without being authenticated on the admin interface.

CVE-2019-14087
Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Failure in buffer management while accessing handle for HDR blit when color modes not supported by display in Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wearables in MSM8909W, QCS605

CVE-2019-12968
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2019 3 PoCs

A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9 to 11 inclusive) distributed with Doomseeker 1.1 and 1.2. Affected plugin versions did not discard IP packets with an unnaturally long response length from a Sonic Robo Blast 2 master server, allowing a remote attacker to cause a potential crash / denial of service in Doomseeker. The issue has been remediated in the Doomseeker 1.3 release with source code patches to the SRB2 plugin.

CVE-2019-9834
Software Genérico General
N/A
UNKNOWN
EPSS
7.9%
2019 2 PoCs

The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot

CVE-2019-9583
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point for other attacks. Affected versions for CCU2: 2.35.16, 2.41.5, 2.41.8, 2.41.9, 2.45.6, 2.45.7, 2.47.10, 2.47.12, 2.47.15. Affected versions for CCU3: 3.41.11, 3.43.16, 3.45.5, 3.45.7, 3.47.10, 3.47.15.

CVE-2019-16758
Software Genérico General
N/A
UNKNOWN
EPSS
18.8%
2019 2 PoCs

In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.

CVE-2019-19929
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.

CVE-2019-15475
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Xiaomi Mi A3 Android device with a build fingerprint of xiaomi/onc_eea/onc:9/PKQ1.181021.001/V10.2.8.0.PFLEUXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.

CVE-2019-11960
HPE Intelligent Management Center (IMC) PLAT General
N/A
UNKNOWN
EPSS
1.6%
2019 1 PoC

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVE-2019-5439
VLC Media Player General
N/A
UNKNOWN
EPSS
17.0%
2019 CWE-120 1 PoC

A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit.

CVE-2019-19993
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnerability were discovered. A user, even with no authentication, may simply send arbitrary content to the vulnerable pages to generate error messages that expose some full paths.

CVE-2019-15371
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Symphony G100 Android device with a build fingerprint of Symphony/G100/G100:8.1.0/O11019/1530618779:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

CVE-2019-5599
FreeBSD General
N/A
UNKNOWN
EPSS
9.6%
2019 4 PoCs

In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow unbounded and cause an expensive list traversal on every packet being processed, leading to resource exhaustion and a denial of service.

CVE-2019-12505
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2019 4 PoCs

Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended. In this way, an attacker can remotely take control over the victim's computer that is operated with an affected receiver of this device.

CVE-2019-14207
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling the clone function due to an endless loop resulting from confusing relationships between a child and parent object (caused by an append error).

CVE-2019-18932
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an existing one in an insecure manner. An attacker can pre-create the directory, and place symlinks in it (after winning a /tmp/sarg/denied.int_unsort race condition). The outcome will be corrupted or newly created files in privileged file system locations.

CVE-2019-8446
Jira General ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 CWE-863 2 PoCs

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVE-2019-11756
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.